Title: Sr Technical Lead-App Development
Area(s) of responsibility
Technical Evaluation & Risk Assessment
Upgrade Monitoring: Track updates, security patches, and lifecycle milestones (End-of-Life/End-of-Support) for all open-source components used across organization portfolios.
Impact Analysis: Evaluate the technical risk of proposed upgrades, identifying potential breaking changes, API deprecations, and compatibility conflicts.
Security & License Review: Assess new versions for introduced security vulnerabilities and verify that license agreements remain compliant with corporate policy.
Communication & Cross-Functional Coordination
Application Team Advisory: Author clear, actionable technical advisories for application teams detailing the urgency, benefits, and breaking changes of required upgrades.
Remediation Planning: Collaborate with product owners and engineering leads to schedule and prioritize critical upgrades within their delivery roadmaps.
Feedback Loop Management: Serve as the primary point of contact for application teams to log, track, and resolve implementation issues discovered during the upgrade process.
Process Automation & Governance
Tooling Optimization: Maintain and configure automated Software Composition Analysis (SCA) and vulnerability scanning tools to trigger alerts for out-of-date components.
Standard Operating Procedures: Define and enforce the step-by-step workflow that application teams must follow to test, validate, and deploy open-source upgrades.
Vulnerability Resolution & Patch Management
Upgrade Monitoring: Monitor security advisories, vulnerability databases, and upstream project releases to identify required security patches and version upgrades.
Risk-Based Evaluation: Evaluate the severity of vulnerabilities (CVSS scores) against the organization's specific architecture to determine the actual runtime risk and exploitability.
Impact & Compatibility Analysis: Assess proposed security upgrades for technical risks, including breaking changes, API deprecations, or regression impacts on existing applications.
Targeted Advisories: Convey actionable remediation paths to application teams, detailing the specific vulnerability details, the required upgrade version, and known migration steps.
SLA Enforcement & Tracking: Coordinate with application owners to ensure security patches are prioritized and deployed within established corporate vulnerability remediation SLAs.
Verification & Testing Support: Partner with development and QA teams to validate that the applied upgrades successfully resolve the vulnerability without introducing system instability.
Below is the indication of Technology stack that is in scope and not just limited to these. Any open source or containers are the th scope.
Core Java / Runtime
OpenJDK — open-source Java Development Kit
Eclipse Temurin — OpenJDK builds from Adoptium
Apache Maven — build and dependency management
Gradle — build automation tool
Web / Application Frameworks
Spring Framework
Spring Boot
Jakarta EE (specification; implementations include open-source servers)
Quarkus
Micronaut
Apache Struts (legacy)
JSF implementations like Mojarra (reference implementation)
Vaadin Framework (community/open-source parts)
Persistence / ORM / Data Access
Hibernate ORM
JPA implementations
MyBatis
Spring Data
jOOQ
Apache Commons DBUtils
Databases
PostgreSQL
MySQL Community Edition
MariaDB
H2 Database
Skills with M/O flag are part of Specialization